Updated
Updated · Arizona's Family · Jul 22
Chick-fil-A Breach Exposes Loyalty Data After 3-Day Credential-Stuffing Attack
Updated
Updated · Arizona's Family · Jul 22

Chick-fil-A Breach Exposes Loyalty Data After 3-Day Credential-Stuffing Attack

3 articles · Updated · Arizona's Family · Jul 22

Summary

  • July 17-19 attacks on Chick-fil-A’s website and mobile apps let unauthorized parties access a limited number of Chick-fil-A One loyalty accounts, prompting the chain to notify affected customers on July 20.
  • Stolen credentials obtained by a third party were used to log in to those accounts, exposing names, email addresses, membership numbers, last four digits of payment cards, and in some cases saved birthdays and addresses.
  • Chick-fil-A forced logouts on affected accounts, removed saved payment methods, restored any impacted loyalty balances, and added extra rewards.
  • Customers were urged to reset passwords and monitor credit reports and account statements, underscoring the broader risk from credential-reuse attacks on loyalty programs.

Insights

After a second breach in three years, is Chick-fil-A’s security fundamentally flawed?
Who is more to blame for data breaches: companies or users who reuse passwords?
As cyberattacks evolve, are passwords finally becoming obsolete for protecting our data?